tcpdump/Wireshark
Command-line and GUI tools for network packet capture and protocol analysis.
tcpdump/Wireshark
Command-line and GUI tools for network packet capture and protocol analysis.
Overview
tcpdump is a command-line packet analyser that captures and displays network traffic in real-time. Wireshark provides a graphical interface with advanced protocol dissection capabilities. Both tools use the libpcap/WinPcap libraries for packet capture and share similar capture filter syntax (BPF - Berkeley Packet Filter), though Wireshark uses its own display filter syntax.
These tools are essential for network troubleshooting, security analysis, protocol development, and understanding network behaviour.
flowchart LR
A[Network Interface] --> B[Capture Filter<br/>BPF Syntax]
B --> C[Packet Capture<br/>tcpdump/Wireshark]
C --> D[Display Filter<br/>Wireshark only]
D --> E[Protocol Analysis]
E --> F[Save to PCAP]
Capture Filter Syntax
Capture filters determine which packets are captured from the network interface. They use Berkeley Packet Filter (BPF) syntax and are applied before packet capture, reducing CPU and storage overhead.
Key Concepts
BPF primitives:
host- Match IP address or hostnamenet- Match network CIDRport- Match port numbersrc/dst- Specify source or destinationtcp/udp/icmp- Match protocolportrange- Match port range
Logical operators:
and(or&&) - Both conditions must be trueor(or||) - Either condition must be truenot(or!) - Negation
Protocol qualifiers:
ether- Ethernet layerip/ip6- IP layertcp/udp- Transport layer
Common Capture Filters
# Capture traffic for specific host
host 192.168.1.100
# Capture traffic to/from specific network
net 192.168.1.0/24
# Capture specific port
port 80
# Capture port range
portrange 8000-9000
# Source and destination
src host 192.168.1.100
dst port 443
# Protocol-specific
tcp port 22
udp port 53
# Multiple conditions with AND
host 192.168.1.100 and port 80
# Multiple conditions with OR
port 80 or port 443
# Exclude traffic (NOT)
not port 22
not host 192.168.1.1
# Complex filters
tcp port 80 and src net 192.168.0.0/16
# HTTP/HTTPS traffic
port 80 or port 443 or port 8080
# DNS queries
udp port 53
# Exclude broadcast and multicast
not broadcast and not multicast
# Capture only SYN packets (TCP flags)
tcp[tcpflags] & tcp-syn != 0 and tcp[tcpflags] & tcp-ack == 0
# Packets larger than N bytes
greater 1000
less 100
Examples
# Capture HTTP traffic from specific host
tcpdump -i eth0 'host 192.168.1.50 and tcp port 80'
# Capture all traffic except SSH
tcpdump -i any 'not port 22'
# Capture traffic between two hosts
tcpdump -i eth0 'host 192.168.1.10 and host 192.168.1.20'
# Capture all traffic to external networks (not RFC1918)
tcpdump -i eth0 'not net 10.0.0.0/8 and not net 172.16.0.0/12 and not net 192.168.0.0/16'
Common Capture Patterns
Pre-configured filters for typical network analysis scenarios.
By Host
# All traffic for specific host
tcpdump host 192.168.1.100
# Traffic from host
tcpdump src host 192.168.1.100
# Traffic to host
tcpdump dst host 192.168.1.100
# Traffic between two hosts
tcpdump host 192.168.1.10 and host 192.168.1.20
# Multiple hosts
tcpdump 'host 192.168.1.10 or host 192.168.1.20 or host 192.168.1.30'
By Port
# Web traffic
tcpdump 'port 80 or port 443'
# SSH traffic
tcpdump port 22
# Mail protocols
tcpdump 'port 25 or port 587 or port 143 or port 993'
# Database traffic
tcpdump 'port 3306 or port 5432 or port 27017'
# Port range
tcpdump portrange 8000-9000
By Protocol
# TCP traffic only
tcpdump tcp
# UDP traffic only
tcpdump udp
# ICMP (ping) traffic
tcpdump icmp
# IPv6 traffic
tcpdump ip6
# ARP traffic
tcpdump arp
# Specific IP protocol number
tcpdump 'ip proto 50' # ESP (IPsec)
Advanced Patterns
# HTTP GET requests
tcpdump -i eth0 -s 0 -A 'tcp port 80 and (tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x47455420)'
# HTTP POST requests
tcpdump -i eth0 -s 0 -A 'tcp port 80 and (tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x504F5354)'
# TCP SYN packets (connection attempts)
tcpdump 'tcp[tcpflags] & tcp-syn != 0'
# TCP RST packets
tcpdump 'tcp[tcpflags] & tcp-rst != 0'
# Fragmented IP packets
tcpdump 'ip[6:2] & 0x3fff != 0'
# IPv4 with TTL less than 5
tcpdump 'ip[8] < 5'
# Broadcast traffic
tcpdump broadcast
# Multicast traffic
tcpdump multicast
tcpdump Command Options
Essential command-line flags for packet capture and output formatting.
Basic Options
# List available interfaces
tcpdump -D
# Capture on specific interface
tcpdump -i eth0
tcpdump -i any # All interfaces
# Limit number of packets
tcpdump -c 100
# Read from capture file
tcpdump -r capture.pcap
# Write to capture file
tcpdump -w output.pcap
# Rotate to a new file every 10 MB (-C is size-based rotation, not append:
# files become output.pcap, output.pcap1, output.pcap2, …)
tcpdump -w output.pcap -C 10
Output Format Options
# Verbose output (more detail)
tcpdump -v
tcpdump -vv # More verbose
tcpdump -vvv # Even more verbose
# Print packets in ASCII
tcpdump -A
# Print packets in HEX and ASCII
tcpdump -X
# Don't resolve hostnames
tcpdump -n
# Don't resolve hostnames or ports
tcpdump -nn
# Show absolute sequence numbers
tcpdump -S
# Capture full packet (not just headers)
tcpdump -s 0 # Modern tcpdump
tcpdump -s 65535 # Older versions
# Timestamp format
tcpdump -t # No timestamp
tcpdump -tt # Unix epoch
tcpdump -ttt # Delta from previous packet
tcpdump -tttt # Human-readable with date
Practical Examples
# Capture HTTP traffic with full packets and ASCII output
tcpdump -i eth0 -s 0 -A 'tcp port 80'
# Capture to file without hostname resolution
tcpdump -i any -nn -w capture.pcap
# Verbose capture of DNS traffic
tcpdump -i eth0 -vvv -s 0 udp port 53
# Capture with timestamps and packet count
tcpdump -i eth0 -tttt -c 1000 host 192.168.1.100
# Rotate capture files (100MB each, max 5 files)
tcpdump -i eth0 -w capture.pcap -C 100 -W 5
# Read and filter existing capture
tcpdump -r input.pcap -nn 'port 443' -w filtered.pcap
# Quick traffic monitoring
tcpdump -i eth0 -nn -q # Quiet mode
Display Filters (Wireshark)
Display filters in Wireshark control which captured packets are shown. Unlike capture filters, they don't affect what's captured and can be changed dynamically.
Key Concepts
Display filters use a different syntax from capture filters:
- Field-based:
protocol.field operator value - Comparisons:
==,!=,>,<,>=,<= - Logical:
and,or,not,xor - Membership:
in,contains,matches(regex)
graph TD
A[Captured Packets] --> B{Display Filter}
B -->|Match| C[Show Packet]
B -->|No Match| D[Hide Packet]
C --> E[Packet List]
style B fill:#f9f,stroke:#333,stroke-width:2px
Common Display Filters
# IP address
ip.addr == 192.168.1.100
ip.src == 192.168.1.100
ip.dst == 192.168.1.100
# Network range
ip.addr == 192.168.1.0/24
# Port
tcp.port == 80
tcp.srcport == 443
tcp.dstport == 8080
# Protocol
http
dns
ssh
tls
icmp
# HTTP methods
http.request.method == "GET"
http.request.method == "POST"
# HTTP status codes
http.response.code == 200
http.response.code >= 400
# HTTP URIs
http.request.uri contains "api"
http.host == "example.com"
# DNS queries
dns.qry.name == "example.com"
dns.flags.response == 0 # Queries only
dns.flags.response == 1 # Responses only
# TCP flags
tcp.flags.syn == 1
tcp.flags.ack == 1
tcp.flags.rst == 1
tcp.flags.fin == 1
# TCP streams
tcp.stream == 5
# Packet length
frame.len > 1000
frame.len < 100
# Time-based
frame.time >= "2024-01-01 00:00:00"
frame.time_delta > 1 # More than 1 second since previous packet
# TLS/SSL
tls.handshake.type == 1 # Client Hello
tls.handshake.type == 2 # Server Hello
ssl.record.content_type == 23 # Application Data
# Multiple conditions
ip.addr == 192.168.1.100 and tcp.port == 80
http or dns
not arp and not icmp
Advanced Display Filters
# Follow TCP conversations
tcp.stream eq 42
# Retransmissions
tcp.analysis.retransmission
# Duplicate ACKs
tcp.analysis.duplicate_ack
# Zero window (receiver buffer full)
tcp.analysis.zero_window
# Connection resets
tcp.flags.reset == 1
# HTTP with specific user agent
http.user_agent contains "curl"
# Contains specific string in payload
frame contains "password"
tcp contains "admin"
# Regular expression matching (escape the backslash inside the quoted string)
http.host matches ".*\\.example\\.com"
# Malformed packets
_ws.malformed
# Expert info (warnings/errors)
_ws.expert.severity == error
_ws.expert.severity == warning
# Packets with specific TTL
ip.ttl < 10
# Fragmented packets
ip.flags.mf == 1 # More fragments flag
# Large packets
tcp.len > 1400
# Specific MAC address
eth.addr == 00:11:22:33:44:55
# VLAN tagged
vlan
# IPv6
ipv6.addr == 2001:db8::1
Filter Expressions
# Bookmarked for quick access
# Save frequently used filters as buttons in Wireshark
# Web browsing traffic
(http or tls) and not (ssdp or mdns)
# Database traffic
tcp.port in {3306, 5432, 1433, 27017}
# Email protocols
tcp.port in {25, 587, 465, 110, 995, 143, 993}
# VoIP traffic
rtp or sip or rtcp
# Network management
snmp or icmp
# File sharing
smb or smb2 or nfs
# Remote access
ssh or rdp or vnc
Protocol Analysis
Understanding and dissecting specific network protocols.
HTTP/HTTPS Analysis
# Wireshark display filters
http
http.request
http.response
# HTTP methods
http.request.method == "GET"
http.request.method == "POST"
http.request.method == "PUT"
http.request.method == "DELETE"
# Status codes
http.response.code == 200 # OK
http.response.code == 404 # Not Found
http.response.code >= 500 # Server errors
# Headers
http.header.name == "Content-Type"
http.cookie contains "session"
# Export HTTP objects
# File → Export Objects → HTTP
# Follow HTTP stream
# Right-click packet → Follow → HTTP Stream
DNS Analysis
# All DNS traffic
dns
# Queries only
dns.flags.response == 0
# Responses only
dns.flags.response == 1
# Specific query type
dns.qry.type == 1 # A record
dns.qry.type == 28 # AAAA record
dns.qry.type == 15 # MX record
dns.qry.type == 16 # TXT record
# Query name
dns.qry.name == "example.com"
dns.qry.name contains "google"
# Response codes
dns.flags.rcode == 0 # No error
dns.flags.rcode == 3 # NXDOMAIN
# DNS over TLS (DoT runs on port 853)
tls && tcp.port == 853
TCP Connection Analysis
sequenceDiagram
participant C as Client
participant S as Server
Note over C,S: Three-Way Handshake
C->>S: SYN
S->>C: SYN-ACK
C->>S: ACK
Note over C,S: Data Transfer
C->>S: Data + ACK
S->>C: ACK
S->>C: Data + ACK
C->>S: ACK
Note over C,S: Connection Termination
C->>S: FIN
S->>C: ACK
S->>C: FIN
C->>S: ACK
# Connection establishment (SYN)
tcp.flags.syn == 1 and tcp.flags.ack == 0
# Connection response (SYN-ACK)
tcp.flags.syn == 1 and tcp.flags.ack == 1
# Connection termination (FIN)
tcp.flags.fin == 1
# Connection reset (RST)
tcp.flags.reset == 1
# Follow TCP stream
# Right-click → Follow → TCP Stream
# TCP stream number
tcp.stream == 0
# TCP analysis flags
tcp.analysis.flags
tcp.analysis.retransmission
tcp.analysis.duplicate_ack
tcp.analysis.lost_segment
tcp.analysis.out_of_order
tcp.analysis.window_full
tcp.analysis.zero_window
# Window size issues
tcp.window_size_value == 0
tcp.window_size_value < 8192
TLS/SSL Analysis
# All TLS traffic
tls
# Handshake messages
tls.handshake.type == 1 # Client Hello
tls.handshake.type == 2 # Server Hello
tls.handshake.type == 11 # Certificate
tls.handshake.type == 16 # Client Key Exchange
# TLS versions (record-layer version field)
tls.record.version == 0x0301 # TLS 1.0
tls.record.version == 0x0302 # TLS 1.1
tls.record.version == 0x0303 # TLS 1.2
tls.record.version == 0x0304 # TLS 1.3
# Caveat: TLS 1.3 pins the record-layer version to 0x0303 on the wire for
# compatibility (the real version is in the supported_versions extension), so
# matching 1.3 by record.version rarely works — filter on tls.handshake.extensions
# or the negotiated tls.handshake.version instead.
# Server Name Indication (SNI)
tls.handshake.extensions_server_name
# Certificate details
x509sat.printableString
x509ce.dNSName
# Alert messages
tls.alert_message
# Decrypt TLS (if you have private key)
# Edit → Preferences → Protocols → TLS → RSA keys list
ICMP Analysis
# All ICMP traffic
icmp
# Ping request
icmp.type == 8
# Ping reply
icmp.type == 0
# Destination unreachable
icmp.type == 3
# Time exceeded (traceroute)
icmp.type == 11
# ICMPv6
icmpv6
Saving and Reading Captures
Managing packet capture files for storage, sharing, and analysis.
Capture File Formats
PCAP (.pcap) - Standard format, widely supported PCAPNG (.pcapng) - Next generation, supports metadata, multiple interfaces
tcpdump File Operations
# Save capture to file
tcpdump -w capture.pcap
# Save with full packet capture
tcpdump -s 0 -w capture.pcap
# Capture with file rotation
tcpdump -w capture.pcap -C 100 # New file every 100MB
tcpdump -w capture.pcap -C 100 -W 10 # Keep max 10 files
# Capture for specific duration
timeout 60 tcpdump -w capture.pcap # 60 seconds
# Read from file
tcpdump -r capture.pcap
# Read and apply filter
tcpdump -r input.pcap 'port 80' -w filtered.pcap
# Read with verbose output
tcpdump -r capture.pcap -vvv -nn
# Display specific packet count from file
tcpdump -r capture.pcap -c 100
# Print packet timestamps
tcpdump -r capture.pcap -tttt
# Combine multiple capture files
mergecap -w combined.pcap file1.pcap file2.pcap file3.pcap
# Split capture file by time
editcap -i 60 input.pcap output.pcap # Split every 60 seconds
# Split capture file by packet count
editcap -c 1000 input.pcap output.pcap # 1000 packets per file
# Remove duplicate packets
editcap -d input.pcap output.pcap
# Extract specific time range
editcap -A "2024-01-01 10:00:00" -B "2024-01-01 11:00:00" input.pcap output.pcap
Wireshark File Operations
# Save entire capture
# File → Save As
# Save filtered packets
# Apply display filter → File → Export Specified Packets
# Save specific packet range
# File → Export Specified Packets → Range
# Export objects (HTTP, SMB, etc.)
# File → Export Objects → [Protocol]
# Merge capture files
# File → Merge
# Import from hex dump
# File → Import from Hex Dump
# Capture file properties
# Statistics → Capture File Properties
tshark (Wireshark CLI)
# Basic capture
tshark -i eth0 -w capture.pcap
# Capture with display filter (after capture)
tshark -i eth0 -Y 'http' -w http.pcap
# Capture with capture filter (before capture)
tshark -i eth0 -f 'port 80' -w capture.pcap
# Read and display
tshark -r capture.pcap
# Read with display filter
tshark -r capture.pcap -Y 'ip.addr == 192.168.1.100'
# Extract specific fields
tshark -r capture.pcap -T fields -e ip.src -e ip.dst -e tcp.port
# JSON output
tshark -r capture.pcap -T json
# Statistics
tshark -r capture.pcap -q -z io,stat,1 # I/O statistics per second
tshark -r capture.pcap -q -z conv,tcp # TCP conversations
# Protocol hierarchy
tshark -r capture.pcap -q -z io,phs
# Extract HTTP URIs
tshark -r capture.pcap -Y http.request -T fields -e http.host -e http.request.uri
# Count packets by protocol
tshark -r capture.pcap -q -z io,phs
Troubleshooting Network Issues
Common network problems and how to diagnose them using tcpdump/Wireshark.
Connection Issues
flowchart TD
A[Connection Problem] --> B{Can you see SYN?}
B -->|No| C[Check routing/firewall]
B -->|Yes| D{See SYN-ACK?}
D -->|No| E[Server not responding<br/>Check firewall/service]
D -->|Yes| F{See ACK?}
F -->|No| G[Client issue<br/>Check client firewall]
F -->|Yes| H{See data transfer?}
H -->|No| I[Application layer issue]
H -->|Yes| J[Connection established<br/>Check latency/errors]
Symptoms: Cannot connect to service
# tcpdump - capture connection attempts
tcpdump -i any -nn 'host TARGET_IP and port TARGET_PORT'
# Wireshark display filters
tcp.flags.syn == 1 and tcp.flags.ack == 0 # SYN packets
tcp.flags.reset == 1 # RST packets
# Check for:
# 1. SYN sent but no SYN-ACK → Firewall or routing issue
# 2. SYN-ACK sent but no ACK → Client-side firewall
# 3. RST received → Service refused connection
# 4. No response at all → Network unreachable
Performance Issues
Symptoms: Slow application performance, timeouts
# Check for retransmissions (tcpdump)
tcpdump -i any -nn 'tcp[tcpflags] & tcp-push != 0'
# Wireshark display filters
tcp.analysis.retransmission # Retransmitted packets
tcp.analysis.duplicate_ack # Duplicate ACKs
tcp.analysis.lost_segment # Lost segments
tcp.analysis.window_full # Window full
tcp.analysis.zero_window # Zero window
frame.time_delta > 1 # Large delays between packets
# Statistics in Wireshark
# Statistics → TCP Stream Graphs → Time Sequence (Stevens)
# Statistics → TCP Stream Graphs → Round Trip Time
# Statistics → I/O Graph
# Check for:
# 1. High retransmission rate → Packet loss
# 2. Zero window → Receiver can't keep up
# 3. Duplicate ACKs → Packet loss or reordering
# 4. Large RTT → Network latency
DNS Issues
Symptoms: Name resolution failures, slow resolution
# Capture DNS traffic
tcpdump -i any -nn 'udp port 53'
# Wireshark display filters
dns.flags.rcode != 0 # DNS errors
dns.flags.rcode == 3 # NXDOMAIN
dns.qry.name == "example.com" # Specific query
frame.time_delta > 1 and dns # Slow responses
# Check for:
# 1. NXDOMAIN responses → Domain doesn't exist
# 2. No response → DNS server unreachable
# 3. Slow responses → DNS server performance issue
# 4. SERVFAIL → DNS server configuration issue
HTTP/Application Issues
Symptoms: HTTP errors, application failures
# Capture HTTP traffic
tcpdump -i any -s 0 -A 'tcp port 80 or tcp port 443'
# Wireshark display filters
http.response.code >= 400 # Client errors
http.response.code >= 500 # Server errors
http.request.method == "POST" # POST requests
http.response.code == 0 # No response
# Follow HTTP stream
# Right-click packet → Follow → HTTP Stream
# Export HTTP objects
# File → Export Objects → HTTP
# Check for:
# 1. 4xx errors → Client-side issues
# 2. 5xx errors → Server-side issues
# 3. Connection reset during transfer → Network or server issue
# 4. Large response times → Server performance issue
Packet Loss Detection
# Check TCP sequence numbers for gaps
tcp.analysis.lost_segment
# Check for out-of-order packets
tcp.analysis.out_of_order
# I/O graph showing packet loss patterns
# Statistics → I/O Graph
# Add filter: tcp.analysis.retransmission
# Calculate packet loss percentage
# Statistics → Capture File Properties
Latency Analysis
# Time-based filters
frame.time_delta > 0.1 # Gaps > 100ms
tcp.time_delta > 0.1 # TCP response delay
# TCP RTT
tcp.analysis.ack_rtt > 0.1 # ACK RTT > 100ms
# Statistics
# Statistics → TCP Stream Graphs → Round Trip Time
# Statistics → I/O Graph with AVG/MIN/MAX filters
# Identify latency sources:
# 1. Network propagation delay
# 2. Server processing time
# 3. Congestion/queuing delay
SSL/TLS Troubleshooting
# Capture TLS handshake
tcpdump -i any -s 0 -nn 'tcp port 443'
# Wireshark display filters
tls.alert_message # TLS alerts
tls.handshake.type == 1 # Client Hello
tls.handshake.type == 2 # Server Hello
# Check for:
# 1. Alert messages → Certificate or cipher issues
# 2. Handshake failures → Version or cipher mismatch
# 3. Certificate validation errors
# 4. Incomplete handshakes → Firewall dropping packets
Broadcast/Multicast Storm
# Capture broadcast traffic
tcpdump -i any broadcast
# Capture multicast traffic
tcpdump -i any multicast
# Wireshark display filters
eth.dst == ff:ff:ff:ff:ff:ff # Broadcast
ip.dst >= 224.0.0.0 # Multicast
# Statistics
# Statistics → Protocol Hierarchy
# Statistics → Conversations
# Statistics → I/O Graph
# Identify source of excessive broadcast/multicast traffic
Quick Reference
tcpdump Essential Commands
| Command | Description |
|---|---|
tcpdump -i eth0 |
Capture on eth0 |
tcpdump -i any |
Capture on all interfaces |
tcpdump -nn |
No hostname/port resolution |
tcpdump -w file.pcap |
Save to file |
tcpdump -r file.pcap |
Read from file |
tcpdump -c 100 |
Capture 100 packets |
tcpdump -s 0 |
Capture full packets |
tcpdump -A |
ASCII output |
tcpdump -X |
Hex and ASCII output |
tcpdump -vvv |
Maximum verbosity |
Common Capture Filters (BPF)
| Filter | Description |
|---|---|
host 192.168.1.1 |
Traffic to/from host |
net 192.168.0.0/24 |
Traffic to/from network |
port 80 |
Traffic on port 80 |
src host 192.168.1.1 |
From specific host |
dst port 443 |
To specific port |
tcp |
TCP traffic only |
udp |
UDP traffic only |
icmp |
ICMP traffic only |
not port 22 |
Exclude SSH |
portrange 8000-9000 |
Port range |
Common Display Filters (Wireshark)
| Filter | Description |
|---|---|
ip.addr == 192.168.1.1 |
IP address |
tcp.port == 80 |
TCP port |
http |
HTTP traffic |
dns |
DNS traffic |
tls |
TLS/SSL traffic |
http.request.method == "GET" |
HTTP GET requests |
http.response.code == 200 |
HTTP 200 responses |
tcp.flags.syn == 1 |
TCP SYN packets |
tcp.analysis.retransmission |
Retransmissions |
frame.time_delta > 1 |
Delays > 1 second |
Protocol Analysis Shortcuts
| Task | Tool/Method |
|---|---|
| Follow TCP conversation | Right-click → Follow → TCP Stream |
| Follow HTTP stream | Right-click → Follow → HTTP Stream |
| Export HTTP objects | File → Export Objects → HTTP |
| View TCP graphs | Statistics → TCP Stream Graphs |
| View protocol hierarchy | Statistics → Protocol Hierarchy |
| View conversations | Statistics → Conversations |
| View endpoints | Statistics → Endpoints |
| I/O statistics | Statistics → I/O Graph |
| Expert information | Analyse → Expert Information |
File Operations
| Task | Command |
|---|---|
| Merge captures | mergecap -w out.pcap in1.pcap in2.pcap |
| Split by time | editcap -i 60 in.pcap out.pcap |
| Split by count | editcap -c 1000 in.pcap out.pcap |
| Remove duplicates | editcap -d in.pcap out.pcap |
| Extract time range | editcap -A "start" -B "end" in.pcap out.pcap |
| Convert format | editcap -F pcap in.pcapng out.pcap |
tshark Quick Commands
| Command | Description |
|---|---|
tshark -i eth0 -w file.pcap |
Capture to file |
tshark -r file.pcap |
Read from file |
tshark -Y 'http' |
Display filter |
tshark -T fields -e ip.src |
Extract field |
tshark -T json |
JSON output |
tshark -q -z io,stat,1 |
I/O statistics |
tshark -q -z conv,tcp |
TCP conversations |
Common Issues and Solutions
| Issue | Cause | Solution |
|---|---|---|
| Permission denied | Requires root/admin | Run with sudo or as administrator |
| Interface not found | Wrong interface name | List interfaces: tcpdump -D or ip link |
| Capture filter not working | Wrong BPF syntax | Check syntax, use man pcap-filter |
| Display filter not working | Wrong Wireshark syntax | Use auto-complete, check protocol fields |
| No packets captured | Wrong interface or filter too restrictive | Use -i any, verify filter |
| Truncated packets | Snaplen too small | Use -s 0 for full packets |
| Can't read PCAP file | Permissions or format | Check file permissions, verify format |
| High CPU usage | Too much traffic without filter | Apply capture filter to reduce load |
| Large capture files | No file rotation | Use -C and -W for rotation |
| Missing packets | Dropped by kernel | Check tcpdump -vvv for drop stats, increase buffer |
| Can't decrypt TLS | No private key | Add private key in Wireshark TLS settings |
| Hostname resolution slow | DNS lookups | Use -nn to disable resolution |
| Wireshark crashes | Corrupted file or bug | Update Wireshark, try editcap to fix file |
| Can't see local traffic | Loopback not captured | Capture on lo interface (Linux) or loopback |
| Packet order wrong | Multiple interfaces | Packets timestamped at different points |
| Export objects fails | Incomplete transfer | Check for TCP retransmissions/errors |